This one came through the official App Store, not a sideload or a jailbreak workaround. A joint investigation by SlowMist and OKX Security found that FomoPeek, a cryptocurrency market-tracking app for iPhone, contained hidden malicious code in versions 1.1 and 1.2 reportedly capable of exploiting the iOS kernel, escaping the app sandbox, and decrypting Keychain data stored on your device. SlowMist says its team analyzed historical IPAs obtained directly from the App Store, confirming the threat was not limited to unofficial or re-signed builds. The malicious versions were reportedly live for eight days before a clean release replaced them.
What FomoPeek Actually Did
Two undisclosed modules hidden inside the official packages gave the app capabilities far beyond anything a crypto price tracker needs.
Two hidden modules, named apptrace and libapptracecore, were embedded inside the App Store packages for versions 1.1 and 1.2, according to SlowMist’s analysis. Those modules had nothing to do with tracking cryptocurrency prices.
SlowMist reported that the kernel-exploitation framework supported eight attack methods, selecting the appropriate exploit based on your specific device model and iOS version. According to the researchers, the affected range covers iOS 12.0 through 18.7 and iOS 26.0 through 26.1.
Sandbox escape is the detail that matters most. iOS normally keeps each app isolated in its own container, limiting its access to files and data belonging to other apps. These modules reportedly broke that barrier. The malicious code could potentially access Keychain-stored passwords, seed phrases, private keys, and data from other apps on the same device, according to SlowMist’s findings.
SlowMist’s version-history analysis places the malicious code’s introduction on September 9, its retention in version 1.2 released September 12, and its reported removal in version 1.3 on September 17.
Why Deleting the App Is Not Enough
SlowMist warned the attack functions could run on a timer, operating in the background without any action from you.
SlowMist warned that the attack functions could execute automatically at regular intervals, meaning the malware may have operated quietly even if you never actively opened the app after installing it. Any sensitive data accessible on that device during that window should be treated as potentially compromised, based on the reported sandbox-escape and Keychain-access capabilities.
Deleting FomoPeek cannot recall information that may already have been extracted. Think of it like food poisoning: removing the dish from the table does nothing about what already happened.
What to Do Now
If FomoPeek 1.1 or 1.2 was ever on your iPhone, the response needs to go further than a simple delete.
If FomoPeek 1.1 or 1.2 was ever on your iPhone, stop using that device for sensitive information immediately. Do not enter or view seed phrases, private keys, or exchange credentials on it.
On a separate, clean device that never had FomoPeek installed, generate a completely new wallet with a fresh seed phrase. Transfer any cryptocurrency from potentially exposed addresses to that new wallet.
Delete FomoPeek from the affected device and install the latest available iOS security update. Updating cannot recover data that may already have left the device, though it may address underlying vulnerabilities the malware reportedly targeted. No Apple advisory confirming the specific patch was available at the time of publication.
Rotate every credential accessible through that iPhone. That includes Keychain passwords, Apple Notes, browser autofill, messaging apps, and any exchange or wallet service you accessed. Review affected wallet addresses for unauthorized transfers and revoke any token approvals where applicable.
For high-value wallets or accounts, the safest path is a complete device erase followed by a clean reinstall from trusted sources, without restoring potentially compromised secrets. For broader guidance on keeping your device secure, see how to stay safe against common mobile threats.
The Bigger Picture
This incident illustrates the gap between marketplace provenance and actual device-level security.
An App Store listing is a distribution channel, not a security guarantee. Anyone holding meaningful cryptocurrency on a general-purpose smartphone should seriously consider a dedicated hardware wallet or an isolated signing device, keeping seed phrases off a phone that also runs dozens of third-party apps.




























